Arch Linux improves package hardening

Discussion in 'all things UNIX' started by summerheat, Oct 24, 2016.

  1. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    On the arch-dev-public mailing list Allan McRae wrote today:
    Definitely good news! So the performance impact of those security flags is smaller than often feared.
     
  2. Anonfame1

    Anonfame1 Registered Member

    Joined:
    May 25, 2016
    Posts:
    224
    Wow- I can't believe they are actually going through with it! That is pure awesome... I had hoped but had a nagging fear it was prolly just talk. Arch has taken a number of strong steps towards security and in a short period of time- they were after all one of the last to have package signing. Then there's linux-grsec, paxd, hardening-wrapper, and now this...

    That places Arch on the shortlist of (potentially) good security distros. Of course, much depends on the user and his/her setup, but the pieces are (almost) all there. About the only weakness Arch will have still is not having an easy MAC option available, though AppArmor (as im sure I've prolly beat to death around here) is very easy to have with a recompiled linux-grsec kernel. I dont include RBAC since it is a pain to maintain over the long haul ;)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.